Faster Firewalls with Bpfilter

17 signa11 1 5/22/2025, 10:37:44 PM lwn.net ↗

Comments (1)

Bender · 11m ago
Modules are not yet supported.

I am probably the exception but I make heavy use of several modules to block bots. I would love to try out bpfilter when they support connlimit, tcpmss, length, limit, owner, recent, set, tcp, ttl and maybe u32. In regards to performance I get some gains using NOTRACK in the raw table for ports I expect high packet rates in combination with stateless rules.